FAIL › dossier
SD-WAN and NetScaler
PRODUCT· dossier confidence 20%
Citrix's SD-WAN and NetScaler products have a history of critical vulnerabilities, most recently an unauthenticated RCE (CVE-2026-8452) that CISA added to its KEV catalog. The company's track record shows a pattern of high-severity flaws being actively exploited before patches are widely deployed.
PROFILE
CategoryNetwork Security / SD-WANWhat they doCitrix provides SD-WAN and NetScaler ADC solutions for secure network traffic management and application delivery.
Websitehttps://www.citrix.com ↗
SECURITY POSTURE
The company has a poor security track record, with multiple high-severity vulnerabilities in its SD-WAN and NetScaler products being actively exploited in the wild, including recent RCE and SQL injection flaws.
Notable failures
- CVE-2019-12991 authenticated RCE
- CVE-2019-12989 active SQL injection
- CVE-2026-8452 unauthenticated RCE
Patterns: repeated unpatched high-severity RCEs; active exploitation of known vulnerabilities
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-03-25 | CVE-2019-12991 | high | Citrix SD-WAN and NetScaler suffered an authenticated command injection flaw that allowed attackers to execute arbitrary commands on the devices. |
| 2022-03-25 | CVE-2019-12989 | high | Citrix SD-WAN and NetScaler suffered a SQL injection vulnerability that was actively exploited in the wild. |
DOSSIER SOURCES
- CISA Orders Urgent Patch for Citrix NetScaler CVE-2026-8452 as Active ... · cvetodo.com
- Citrix NetScaler CVE-2026-8452 KEV: Patch ADC and Gateway · fixitphill.com
- CISA: Patch Citrix NetScaler CVE-2026-8452; attacks reported · www.cloudlinktech.com
Open questions: Citrix's current patch cadence for SD-WAN and NetScaler · Whether Citrix has implemented compensating controls for CVE-2026-8452
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-30 04:11:29.754453+00:00